How we treat your data
What's in place today, what isn't yet, and where to send a questionnaire or a vulnerability report. No hand-waving.
What's in place, what isn't
- in place per-workspace isolation by row-level policies · HMAC-verified Stripe, Shopify and Instagram webhooks · TLS in transit via Cloudflare · secrets outside code and images, with an age check · monthly backup-restore drill · no model training on customer data
- not yet SOC 2 · SAML/SCIM · a published penetration test · EU data residency · customer-managed keys
questionnaires and DPAs: hello@selify.ai — we answer them; we don't yet have a self-service trust portal.
How the platform is built
Workspace isolation
Every workspace-scoped table is filtered by workspace in application code and again by a row-level policy in Postgres, and every RPC that returns workspace data takes the workspace as a parameter. Realtime subscriptions are filtered server-side.
Webhook integrity
Stripe, Shopify and Instagram webhooks are verified against their signing secrets before any side effect runs. Billing writes are idempotent per event.
Secrets
Production secrets live in the runtime environment, never in code or container images; build-time variables are public-only. A scheduled job flags secrets that have gone unrotated too long.
Backups
Database backups are restored to a scratch instance on a monthly schedule to prove they work.
Inference
Text models run via API under Selify's account. Open-weights vision and imaging models (photo reading, virtual try-on, background removal) run on Selify's own on-demand GPU capacity, scaled to zero when idle. We do not fine-tune or train any model on customer data.
Authentication
Email and password sign-in with hosted auth; Shopify and social accounts connect over OAuth. Internal admin tooling sits behind a separate NDA and IP-allowlist gate.
Audit
Long-running operations execute as durable workflows with full event history; admin actions write to an audit log keyed by actor.
Frequently asked
Where is data stored?
Who can see customer conversations?
Are prompts used to train models?
Do you support SSO?
Can we get a questionnaire or DPA answered?
Report a vulnerability
Found something? Email hello@selify.ai. We read every report and reply to each one; researchers who want credit get it.
legal entity: Up Go Corp. (Ontario, Canada) · questionnaires and DPAs: hello@selify.ai